{"id":"CVE-2018-15587","details":"GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.","modified":"2026-04-11T11:50:12.721389Z","published":"2019-02-11T17:29:00.270Z","related":["SUSE-SU-2019:1266-1","SUSE-SU-2019:1266-2","SUSE-SU-2019:1391-1","SUSE-SU-2019:1391-2","openSUSE-SU-2019:1431-1","openSUSE-SU-2019:1453-1","openSUSE-SU-2024:10743-1"],"database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00047.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00061.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00024.html"},{"type":"WEB","url":"https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Jun/7"},{"type":"WEB","url":"https://usn.ubuntu.com/3998-1/"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Apr/38"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2019/04/30/4"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00027.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4457"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=796424"},{"type":"PACKAGE","url":"https://github.com/RUB-NDS/Johnny-You-Are-Fired"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/evolution","events":[{"introduced":"0"},{"last_affected":"1ef6a4cbab1ffe06c56c96e1d05c85a07f514f19"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.28.2"}],"source":"CPE_FIELD"}}],"versions":["3.27.4","3.27.90","3.27.91","3.27.92","3.28.0","3.28.1","3.28.2","EVOLUTION_2_11_3","EVOLUTION_2_11_4","EVOLUTION_2_11_5","EVOLUTION_2_11_90","EVOLUTION_2_11_91","EVOLUTION_2_11_92","EVOLUTION_2_21_1","EVOLUTION_2_21_2","EVOLUTION_2_21_3","EVOLUTION_2_21_4","EVOLUTION_2_21_90","EVOLUTION_2_21_91","EVOLUTION_2_22_0","EVOLUTION_2_23_1","EVOLUTION_2_23_2","EVOLUTION_2_23_3","EVOLUTION_2_23_4","EVOLUTION_2_23_5","EVOLUTION_2_23_6","EVOLUTION_2_23_90","EVOLUTION_2_23_91","EVOLUTION_2_25_1","EVOLUTION_2_25_2","EVOLUTION_2_25_3","EVOLUTION_2_25_4","EVOLUTION_2_25_5","EVOLUTION_2_25_90","EVOLUTION_2_25_92","EVOLUTION_2_26_0","EVOLUTION_2_26_1","EVOLUTION_2_27_3","EVOLUTION_2_27_4","EVOLUTION_2_27_5","EVOLUTION_2_27_90","EVOLUTION_2_29_1","EVOLUTION_2_29_3","EVOLUTION_2_29_3_1","EVOLUTION_2_29_4","EVOLUTION_2_29_5","EVOLUTION_2_29_6","EVOLUTION_2_29_90","EVOLUTION_2_29_92","EVOLUTION_2_31_1","EVOLUTION_2_31_2_CORRECTED","EVOLUTION_2_31_3","EVOLUTION_2_31_3_1","EVOLUTION_2_31_4","EVOLUTION_2_31_5_CORRECTED","EVOLUTION_2_31_6","EVOLUTION_2_31_90","EVOLUTION_2_31_91","EVOLUTION_2_31_92","EVOLUTION_2_91_0","EVOLUTION_2_91_1","EVOLUTION_2_91_2","EVOLUTION_2_91_3","EVOLUTION_2_91_4","EVOLUTION_2_91_5","EVOLUTION_2_91_6","EVOLUTION_2_91_90","EVOLUTION_2_91_91","EVOLUTION_2_91_92","EVOLUTION_3_10_0","EVOLUTION_3_11_1","EVOLUTION_3_11_2","EVOLUTION_3_11_3","EVOLUTION_3_11_4","EVOLUTION_3_11_5","EVOLUTION_3_11_90","EVOLUTION_3_11_91","EVOLUTION_3_12_0","EVOLUTION_3_13_1","EVOLUTION_3_13_10","EVOLUTION_3_13_2","EVOLUTION_3_13_3","EVOLUTION_3_13_4","EVOLUTION_3_13_5","EVOLUTION_3_13_6","EVOLUTION_3_13_7","EVOLUTION_3_13_8","EVOLUTION_3_13_9","EVOLUTION_3_13_90","EVOLUTION_3_15_91","EVOLUTION_3_15_92","EVOLUTION_3_16_0","EVOLUTION_3_17_1","EVOLUTION_3_17_2","EVOLUTION_3_17_3","EVOLUTION_3_17_4","EVOLUTION_3_17_90","EVOLUTION_3_17_91","EVOLUTION_3_17_92","EVOLUTION_3_18_0","EVOLUTION_3_19_1","EVOLUTION_3_19_2","EVOLUTION_3_19_3","EVOLUTION_3_19_4","EVOLUTION_3_19_90","EVOLUTION_3_19_91","EVOLUTION_3_19_92","EVOLUTION_3_1_1","EVOLUTION_3_1_3","EVOLUTION_3_1_4","EVOLUTION_3_1_5","EVOLUTION_3_1_90_FIXED","EVOLUTION_3_1_91","EVOLUTION_3_1_92","EVOLUTION_3_20_0","EVOLUTION_3_21_1","EVOLUTION_3_21_2","EVOLUTION_3_21_3","EVOLUTION_3_21_4","EVOLUTION_3_21_90","EVOLUTION_3_21_91","EVOLUTION_3_21_92","EVOLUTION_3_22_0","EVOLUTION_3_23_1","EVOLUTION_3_23_2","EVOLUTION_3_23_3","EVOLUTION_3_23_4","EVOLUTION_3_23_90","EVOLUTION_3_23_91","EVOLUTION_3_23_92","EVOLUTION_3_24_0","EVOLUTION_3_25_1","EVOLUTION_3_25_2","EVOLUTION_3_25_3","EVOLUTION_3_25_4","EVOLUTION_3_25_90","EVOLUTION_3_25_91","EVOLUTION_3_25_92","EVOLUTION_3_25_92_1","EVOLUTION_3_25_92_2","EVOLUTION_3_26_0","EVOLUTION_3_27_1","EVOLUTION_3_27_2","EVOLUTION_3_27_3","EVOLUTION_3_2_0","EVOLUTION_3_3_2","EVOLUTION_3_3_3","EVOLUTION_3_3_4","EVOLUTION_3_3_5","EVOLUTION_3_3_90","EVOLUTION_3_3_91","EVOLUTION_3_3_92","EVOLUTION_3_4_0","EVOLUTION_3_5_1","EVOLUTION_3_5_3","EVOLUTION_3_5_4","EVOLUTION_3_5_5","EVOLUTION_3_5_90","EVOLUTION_3_5_91","EVOLUTION_3_5_92","EVOLUTION_3_7_1","EVOLUTION_3_7_2_FIXED","EVOLUTION_3_7_3","EVOLUTION_3_7_4_FIXED","EVOLUTION_3_7_90","EVOLUTION_3_7_91","EVOLUTION_3_7_92","EVOLUTION_3_9_2","EVOLUTION_3_9_3","EVOLUTION_3_9_4","EVOLUTION_3_9_5","EVOLUTION_3_9_90","EVOLUTION_3_9_91","EVOLUTION_3_9_92","GNOME_0_12","GNOME_0_20","GNOME_0_20a","GNOME_0_25","GNOME_0_27"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-15587.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}